US11153344B2ActiveUtilityA1

Establishing a protected communication channel

Assignee: TRUSTONIC LTDPriority: Sep 17, 2018Filed: Sep 12, 2019Granted: Oct 19, 2021
Est. expirySep 17, 2038(~12.2 yrs left)· nominal 20-yr term from priority
Inventors:Richard Hayton
H04L 9/14H04L 9/0866H04L 9/0825H04L 9/0869H04L 9/083H04L 63/18H04L 63/0442H04L 63/0435H04L 63/06H04L 9/3215H04L 2209/805H04L 9/0838H04L 9/0827H04L 9/0643
93
PatentIndex Score
12
Cited by
6
References
12
Claims

Abstract

To establish a first protected communication channel between a device D and a first server S, a symmetric key K S is derived at the device D, based on a device identifying key K D and public key information dependent on a first server public key S public of the first server S. The symmetric key K S is derived in a corresponding way at a second server T. The symmetric key K S is transmitted from the second server T to the first server S on a second protected communication channel. Communication on the first protected communication channel between the device D and the first server S is protected using a communication key K C which is dependent on the symmetric key K S . This can enable a device D lacking support for asymmetric key cryptography to securely enter into communication with the first server S.

Claims

exact text as granted — not AI-modified
The invention claimed is: 
     
       1. A method for establishing a first protected communication channel between a device and a first server, the first server having a first server public key, and the device having a device identifying key shared with a second server different from the first server, the method comprising:
 deriving a symmetric key at the device, based on the device identifying key and public key information dependent on the first server public key; 
 sending, by the device, a payload message to the first server on the first protected communication channel protected using a communication key which is dependent on the symmetric key; 
 in response to the payload message, the first server sends a key generation request to the second server to trigger the second server to derive the symmetric key and transmit the symmetric key to the first server on a second protected communication channel; 
 deriving the symmetric key at the second server, based on the device identifying key and the public key information; and 
 transmitting the symmetric key from the second server to the first server using the second protected communication channel. 
 
     
     
       2. The method of  claim 1 , in which the second protected communication channel is protected using a public key infrastructure based on asymmetric keys. 
     
     
       3. The method of  claim 2 , in which the asymmetric keys for the public key infrastructure comprise said first server public key and a first server private key. 
     
     
       4. The method of  claim 1 , in which the communication key is the same as the symmetric key. 
     
     
       5. The method of  claim 1 , in which the communication key is derived from the symmetric key based on information shared between the device and the first server. 
     
     
       6. The method of  claim 5 , in which the information shared between the device and the first server comprises at least one of:
 a class key associated with a class of devices including the device; and 
 a random or pseudorandom value. 
 
     
     
       7. The method of  claim 1 , in which the public key information is the same as the first server public key. 
     
     
       8. The method of  claim 1 , in which the public key information comprises a hash of the first server public key, and has fewer bits than the first server public key. 
     
     
       9. The method of  claim 1 , in which the device is incapable of generation of asymmetric keys for supporting a public key infrastructure. 
     
     
       10. The method of  claim 1 , in which the payload message and the key generation request each specify a device identifier of the device. 
     
     
       11. At least one non-transitory, computer-readable storage medium storing one or more computer programs, which when executed by one or more data processors in a device, a first server, and a second server different from the first server, cause the one or more data processors to establish a first protected communication channel between the device and the first server, where the first server has a first server public key and the device has a device identifying key shared with the second server by:
 deriving a symmetric key at the device, based on the device identifying key and public key information dependent on the first server public key; 
 sending, by the device, a payload message to the first server on the first protected communication channel protected using a communication key which is dependent on the symmetric key; 
 in response to the payload message, the first server sending a key generation request to the second server to trigger the second server to derive the symmetric key and transmit the symmetric key to the first server on a second protected communication channel; 
 deriving the symmetric key at the second server, based on the device identifying key and the public key information; and 
 transmitting the symmetric key from the second server to the first server using the second protected communication channel. 
 
     
     
       12. A system comprising:
 a device; 
 a first server; and 
 a second server different from the first server, 
 each of the device, the first server, and the second server comprising:
 corresponding processing circuitry to perform data processing; and 
 data storage, 
 
 wherein each data storage stores one or more computer programs for controlling corresponding processing circuitry to establish a first protected communication channel between the device and the first server, the first server having a first server public key, and the device having a device identifying key shared with the second server by: 
 deriving a symmetric key at the device, based on the device identifying key and public key information dependent on the first server public key; 
 sending, by the device, a payload message to the first server on the first protected communication channel protected using a communication key which is dependent on the symmetric key; 
 in response to the payload message, the first server sends a key generation request to the second server to trigger the second server to derive the symmetric key and transmit the symmetric key to the first server on a second protected communication channel; 
 deriving the symmetric key at the second server, based on the device identifying key and the public key information; and 
 transmitting the symmetric key from the second server to the first server using the second protected communication channel.

Join the waitlist — get patent alerts

Track US11153344B2 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.